Skip to content

Commit

Permalink
Auto import
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions committed May 25, 2023
1 parent c86ecf1 commit a6800af
Showing 1 changed file with 31 additions and 0 deletions.
31 changes: 31 additions & 0 deletions vulns/mlflow/PYSEC-0000-CVE-2023-2780.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
id: PYSEC-0000-CVE-2023-2780
details: 'Path Traversal: ''\..\filename'' in GitHub repository mlflow/mlflow prior
to 2.3.1.'
affected:
- package:
name: mlflow
ecosystem: PyPI
purl: pkg:pypi/mlflow
ranges:
- type: GIT
repo: https://github.com/mlflow/mlflow
events:
- introduced: "0"
- fixed: fae77a525dd908c56d6204a4cef1c1c75b4e9857
- type: ECOSYSTEM
events:
- introduced: "0"
- fixed: 2.3.1
references:
- type: EVIDENCE
url: https://huntr.dev/bounties/b12b0073-0bb0-4bd1-8fc2-ec7f17fd7689
- type: FIX
url: https://huntr.dev/bounties/b12b0073-0bb0-4bd1-8fc2-ec7f17fd7689
- type: WEB
url: https://huntr.dev/bounties/b12b0073-0bb0-4bd1-8fc2-ec7f17fd7689
- type: FIX
url: https://github.com/mlflow/mlflow/commit/fae77a525dd908c56d6204a4cef1c1c75b4e9857
aliases:
- CVE-2023-2780
modified: "2023-05-25T17:26:00Z"
published: "2023-05-17T21:15:00Z"

0 comments on commit a6800af

Please sign in to comment.